Analysts are treating the claim with skepticism for several reasons:
Before ShinyHunters' claim, EY had already disclosed a separate, confirmed data breach involving a third-party IT service management (ITSM) platform used for internal support tickets. Key details:
The confirmed third-party breach and the ShinyHunters claim are not the same incident — the former is a documented event EY disclosed; the latter is an unsubstantiated claim that may or may not be connected.
ShinyHunters has been one of the most prolific data-theft and extortion groups of 2026, operating a consistent "breach, exfiltrate, demand, and publish-or-sell" model. Major 2026 campaigns include:
| Target | Month | Details |
|---|---|---|
| Salesforce Experience Cloud victims | March 2026 | Exploited misconfigured Aura endpoints, hitting hundreds of orgs including Qantas, Allianz Life, LVMH, Adidas, Google, Workday |
| Instructure Canvas LMS | May 2026 | Breached twice in 10 days via XSS in Free-for-Teacher accounts; exfiltrated ~3.6 TB of data affecting 275M+ student records. FBI issued a PSA. |
| Council of Europe | June 2026 | Claimed theft of 297 GB (429,000+ files) of HR and operational data; threatened release by June 16 |
| Kodak | June 2026 | Claimed 2.2 million records of customer PII; set a June 18 leak deadline; Kodak later confirmed the breach |
| Abbott Laboratories | July 2026 | Posted Abbott on its leak site with a July 18 deadline, later postponed to July 21 |
| Ernst & Young | July 2026 | Claimed supply-chain breach; deadline July 31 (unsubstantiated as of this writing) |
The group's tradecraft relies on voice phishing (vishing), credential theft, OAuth token abuse, and supply-chain compromise rather than encryption-based ransomware. Analysts also note that ShinyHunters has re-extorted victims after payment — most notably in the PowerSchool case — making negotiation a risky strategy.
The FBI, Mandiant, and EclecticIQ have all issued advisories tracking ShinyHunters as a financially motivated, extortion-as-a-service collective that has expanded rapidly through AI-enabled social engineering and SaaS platform exploitation.